SIM Swapping
SIM Swapping is a fraudulent activity where an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card controlled by the attacker. Once the attacker has control of the phone number, they can bypass SMS-based two-factor authentication to gain access to sensitive accounts, including crypto exchange logins.
This is a significant threat in the digital asset space, as it exploits the reliance on legacy telecommunications infrastructure for security. Because SMS is not encrypted or designed for authentication, it is highly susceptible to social engineering.
Moving away from SMS-based MFA to hardware-based FIDO2 standards is the most effective way to prevent this type of attack. SIM swapping highlights the importance of choosing robust, hardware-backed security measures over convenience-oriented, software-based solutions.
It serves as a reminder that the security of a system is only as strong as its weakest link.